SHANG Wen-li, ZHANG Sheng-shan, WAN Ming, et al. Modbus/TCP Communication Anomaly Detection Algorithm Based on PSO-SVM[J]. Acta Electronica Sinica, 2014, 42(11): 2314-2320.
DOI:
SHANG Wen-li, ZHANG Sheng-shan, WAN Ming, et al. Modbus/TCP Communication Anomaly Detection Algorithm Based on PSO-SVM[J]. Acta Electronica Sinica, 2014, 42(11): 2314-2320. DOI: 10.3969/j.issn.0372-2112.2014.11.029.
Modbus/TCP Communication Anomaly Detection Algorithm Based on PSO-SVM
To detect and defend industry virus attacks to application layer protocol data is difficult issues in study of industrial security gateway.In this paper
a data pre-processing method is presented
which can convert Modbus TCP traffic into anomaly detection model
and a PSO-SVM algorithm is designed
which optimizes parameters by advanced Particle Swarm Optimization (PSO) algorithm.The method identifies anomalies of Modbus TCP traffic according to appear frequencies of the mode short sequence of Modbus function code sequence.Finally
experimental data analysis shows that the proposed method can effectively detect abnormal of Modbus function code sequence.